SwissHub
The Swiss FADP Compliance Checklist for Digital Mail Handling (2025 Edition)
Compliance8 min read

The Swiss FADP Compliance Checklist for Digital Mail Handling (2025 Edition)

Stop guessing: this 10-point checklist shows how to keep every scanned letter FADP-ready—and how SwissHub automates half the work.

1. Understand the revised FADP (in force since 1 Sep 2023)

The law tightened breach-notification deadlines and introduced a record-of-processing obligation.[secureprivacy.ai],[lexology.com]

Key Changes:

  • • Data breach notification within 72 hours
  • • Mandatory record of processing activities
  • • Stricter consent requirements
  • • Enhanced individual rights

2. Map physical letters to "personal data"

Tax slips, medical letters, even address labels are all covered. Under FADP, personal data includes any information relating to an identified or identifiable natural person.

Common mail types and their data classification:

  • âś“ Invoices - Contains names, addresses, purchase history
  • âś“ Bank statements - Financial data, transaction history
  • âś“ Insurance documents - Health information, personal details
  • âś“ Tax forms - Income data, social security numbers
  • âś“ Medical correspondence - Sensitive health data (special category)

3. Choose a Swiss-hosted processor

ePost scans remain in Swiss datacentres; SwissHub processes and stores metadata exclusively in Zurich & Geneva regions.

Swiss hosting advantages:

  • • No cross-border data transfers
  • • Swiss Federal Data Protection Act applies
  • • Strong privacy laws and enforcement
  • • No foreign surveillance laws

4. Minimise data transfers

Use SwissHub's on-the-fly classification so only the PDF—and never the raw image—is forwarded to Gmail/SharePoint.

Data minimization in practice:

  1. 1. Raw scan stays in Swiss ePost servers
  2. 2. SwissHub extracts only necessary metadata
  3. 3. PDF is encrypted before any transfer
  4. 4. Only classified data leaves Switzerland (if configured)

5. Enable role-based access & logs

SwissHub writes immutable access logs you can export during a DPIA (Data Protection Impact Assessment).

Log TypeInformation CapturedRetention
Access logsUser ID, timestamp, action, resource90 days
Processing logsDocument ID, processing steps, results180 days
Consent logsUser consent, timestamp, scopeIndefinite

FAQ Rich Snippet

Q: Is encrypting the PDF alone enough for FADP?

A: No. You must also hash the file name or strip identifying info because filenames count as personal data.

The Complete 10-Point FADP Checklist

  1. 1
    Data Inventory - Document all mail types and personal data categories
  2. 2
    Legal Basis - Establish lawful grounds for processing (consent, contract, legal obligation)
  3. 3
    Swiss Hosting - Ensure all data remains in Swiss data centers
  4. 4
    Encryption - Implement end-to-end encryption for all documents
  5. 5
    Access Control - Set up role-based permissions and multi-factor authentication
  6. 6
    Audit Logs - Enable comprehensive logging for all access and processing
  7. 7
    Data Minimization - Process only necessary data, delete when no longer needed
  8. 8
    Breach Protocol - Establish 72-hour notification procedures
  9. 9
    Individual Rights - Implement processes for access, rectification, deletion requests
  10. 10
    Regular Reviews - Conduct quarterly compliance assessments

How SwissHub Automates Compliance

Automatic Features

  • âś“ Swiss-only data residency
  • âś“ Encrypted storage & transfer
  • âś“ Immutable audit logs
  • âś“ Role-based access control
  • âś“ Automatic data retention

Compliance Reports

  • âś“ Processing activity records
  • âś“ Access history exports
  • âś“ Data inventory reports
  • âś“ Consent tracking
  • âś“ DPIA templates

Implementation Timeline

Week 1-2
Data inventory & risk assessment
Week 3-4
Configure SwissHub compliance settings
Week 5-6
Staff training & documentation
Week 7-8
Compliance audit & certification

Get Your FADP Compliance Assessment

Our compliance experts can review your current setup and provide recommendations

The Swiss FADP Compliance Checklist for Digital Mail Handling (2025 Edition) | SwissHub | SwissHub